Privacy Policy

Last updated: 2025-11-05

This Privacy Policy applies to WHOX products and services, including our website at whox.is, our mobile and desktop apps, and our browser extensions (the «Services»). «WHOX», «we», «our» or «us» means’ ’Sam digital solutions FZE, a company registered in a UAE free zone. By accessing or using the Services you acknowledge this Policy.

1) Definitions

  • Personal Data means information relating to an identified or identifiable natural person. De‑identified or aggregated information is not Personal Data.
  • Processing means any operation performed on Personal Data (collection, storage, use, disclosure, etc.).
  • Controller determines purposes and means of Processing.Processor processes on behalf of a controller.
  • Services means our website, apps, VPN and browser extensions distributed under the WHOX brand.

2) Controller & Contact

Controller: Sam digital solutions FZE, a company registered in a UAE free zone.

Privacy contact: [email protected]

EEA/UK targeting: We do not directly target individuals in the EEA or the UK and do not monitor their behavior; accordingly, appointment of an EU/UK representative under GDPR Art. 27 is not required at this time. We will reassess and appoint one if our targeting changes.

3) Scope & Products

This Policy covers the WHOX VPN, the WHOX website, our apps for iOS/Android/macOS/Windows, and our browser extensions. It does not apply to third‑party websites or services.

4) Our No‑Logs Commitment

WHOX is a no‑logs VPN. We do not collect or store traffic content, browsing history, DNS queries, destination IP addresses, per‑user bandwidth, connection timestamps, or the IP address assigned to you by our VPN servers.

To keep the Services secure and reliable, we may process minimal non‑identifying technical telemetry (e.g., app version, device OS, crash diagnostics, generic performance metrics). Such telemetry does not include your browsing activity and is not used to identify you. We donot collect advertising identifiers (e.g.,IDFA/GAID).

5) Summary of Processing

CategoryExamplesPurposeLegal BasisRetention
Account & PaymentsEmail (if provided), subscription status; payments viaStripe (cards), Apple App Store /Google Play (IAP),Cryptomus (crypto).Provide paid features, billing, support, compliance.Contract; Legal obligation.Kept only as long as needed for billing, tax/audit, fraud/chargeback handling, and applicable limitation periods.
Website operationsEssential cookies; server and security logs (via CDN/WAF).Operate, secure and debug the website; investigate incidents.Legitimate interests; Legal obligation (security).Retained for the shortest period necessary for operations and security; extended during active investigations or legal holds.
Analytics (Google Analytics)Page views, referrers, device/OS/browser, approximate geolocation, and similar usage metrics collected byGoogle Analytics (GA4).Measure and improve site usage and performance on an aggregate basis.Consent where required (e.g., EEA/UK); otherwise legitimate interests where permitted.Retention is controlled in our GA4 property and may vary by configuration/region; we choose the minimum practical setting and review periodically.
Support communicationsInformation you provide in emails or forms.Respond to requests and resolve issues.Contract; Legitimate interests.Kept only as long as needed to resolve and follow‑up, subject to legal holds.

We apply data minimization and storage limitation and keep information only as long as necessary for the stated purposes.

6) Purposes of Processing

  • Provide and maintain the Services you request (VPN connectivity and features);
  • Ensure security, prevent abuse and fraud, detect and resolve incidents;
  • Improve performance and quality (e.g., crash diagnostics, app updates);
  • Audience measurement to understand website usage and improve UX (Google Analytics);
  • Comply with legal obligations (e.g., finance/tax, fraud prevention);
  • Where applicable, provide analytics or communications with your consent.

7) Legal Bases (EU/UK/CH)

  • Contract — to provide the Services and features you request.
  • Legitimate interests — to keep the Services secure and reliable, prevent abuse, improve quality, and perform high‑level audience measurement (balanced against your rights).
  • Consent — for non‑essential cookies/SDKs (e.g., Google Analytics) and where required by law.
  • Legal obligations — to comply with applicable laws.

8) Cookies & Consent

We do not run programmatic advertising on our website. We use essential cookies and storage strictly necessary to operate the site (e.g., load balancing, security).

We also use Google Analytics (GA4) to understand how our site is used in aggregate. In the EEA/UK (and other regions where required by law), we load Google Analytics only after you chooseAccept (non‑essential cookies are not set afterReject). Outside those regions, we rely on legitimate interests where permitted. Learn more about how Google uses data: Google Partner Sites, and see Google’s privacy policy: Google Privacy. You can opt out of Google Analytics by using the GA Opt‑out Browser Add‑on.

9) App Stores & Browser Extensions

When you purchase via Apple App Store orGoogle Play, Apple or Google acts as theindependent controller for those transactions and processes data according to their policies. Our apps request only the minimum permissions necessary for functionality (e.g., VPN configuration, network access). For browser extensions distributed via Chrome Web Store, Firefox Add‑ons or other stores, we request permissions strictly required for features and disclose them in the store listing.

10) WHOX browser extension

The WHOX browser extension applies privacy recipes derived from public diagnostics (such as leak checks) to reduce browser‑level anonymity gaps (for example, WebRTC and DNS leaks). Processing occurs primarily on‑device and in‑browser. The extension may periodically fetch rule updates from WHOX endpoints. We do not collect your browsing history, page content, or the list of websites you visit through the extension. You can disable the extension at any time via your browser settings.

11) Disclosures, Recipients & Sub‑processors

We may disclose Personal Data to trusted service providers who act on our instructions and under contract. In particular:

  • Google LLC (Google Analytics) — non‑essential analytics (GA4) to measure aggregated usage; acts as our processor under applicable Google Measurement Data Processing Terms. Privacy: policies.google.com/privacy; GA opt‑out: tools.google.com/dlpage/gaoptout; partner sites: policies.google.com/technologies/partner-sites.
  • Stripe — payment processing, anti‑fraud and compliance services. Stripe acts as our processor for payments we initiate; for its own regulatory/anti‑fraud purposes, Stripe may act as an independent controller. We do not store full card numbers. See Stripe’s UAE Privacy Policy:stripe.com/en-ae/privacy.
  • Apple App Store / Google Play — for in‑app purchases, Apple or Google acts as the independent controller for the transaction.
  • Cryptomus (crypto payments) — gateway for cryptocurrency payments. Cryptomus processes wallet addresses, transaction identifiers, amounts and currency, and may perform anti‑fraud and sanctions/AML screening. For payments we initiate it acts as our’ ’processor; for its regulatory/anti‑fraud obligations it may act as anindependent controller. We do not custody your private keys. Privacy: cryptomus.com/privacy.
  • Banks / card networks — in case of disputes/chargebacks, relevant transaction information may be shared with issuing banks and card networks to resolve the dispute.

Our Sub‑processors

All processors are bound by confidentiality and security obligations and may not use data for their own purposes. We do not sell or share Personal Data for cross‑context behavioral advertising.

Blockchain transparency

Cryptocurrency transactions are recorded on public distributed ledgers that are replicated globally and may be accessible indefinitely. These ledgers are outside of our control; requests for deletion or correction cannot be applied to on‑chain records. Where feasible, we will delete or de‑identify any off‑chain data we control that are linked to a transaction.

12) Retention

We follow the principle of storage limitation and keep Personal Data no longer than necessary for the purposes described in this Policy. Where it is not possible to specify an exact period, we determine retention by applying criteria including:

  • Legal and regulatory requirements (e.g., finance/tax, accounting, anti‑fraud, sanctions/AML obligations, and applicable limitation periods);
  • Security and incident response needs (retaining logs for the shortest period needed to detect, investigate and remediate threats, with extensions during active investigations or legal holds);
  • Operational necessity to provide the Services, handle support, and ensure reliability/quality;
  • User choice (e.g., deletion requests) and our data minimisation reviews.

For analytics, retention is controlled within ourGoogle Analytics (GA4) property and may vary by configuration and region. We select the minimum practical setting and review it periodically.

13) International Data Transfers

Where Personal Data are transferred across borders, we rely on appropriate safeguards such as EUStandard Contractual Clauses (2021/914), the UKIDTA/Addendum, Swiss FDPIC‑aligned safeguards, and supplementary measures where required. This includes transfers necessary forGoogle Analytics, Stripe,Cryptomus and app store transactions. We maintain contractual safeguards with our processors and assess their sub‑processors and locations as part of vendor due diligence.

Public blockchain networks used for cryptocurrency payments operate globally; on‑chain data may be processed outside your jurisdiction and retained indefinitely by the network.

14) Your Privacy Rights

Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object, and data portability, and to withdraw consent. We respond within legally required timeframes and may request limited information to verify your identity before responding. To exercise rights, contact us at [email protected]. You may also lodge a complaint with your local supervisory authority (including, where applicable, the UAE Data Office).

15) US State Privacy

We comply with applicable US state privacy laws where relevant and do not sell or share Personal Data for cross‑context behavioral advertising.

16) UAE PDPL

As an entity established in the UAE, we align with the UAE Federal Decree‑Law No. 45 of 2021 on the Protection of Personal Data (PDPL).Small scale and current processing: given our small scale and absence of high‑risk or large‑scale processing, we have assessed that appointment of a Data Protection Officer (DPO) is not required at this time and that a Data Protection Impact Assessment (DPIA) is not required for our present operations. We will re‑assess these conclusions as our scale or processing activities change. We actively monitor forthcoming executive regulations to update this Policy if new binding requirements arise.

Payments & CBUAE alignment: We rely on licensed payment service providers to process payments. Our integrations are designed to respect the Central Bank of the UAE’s Consumer Protection Regulation and Standards and the Retail Payment Services and Card Schemes Regulation applicable to licensed financial institutions and their providers. We do not provide regulated payment services, do not store full card numbers, and do not custody customer funds or crypto private keys.

17) Service Availability & Local Restrictions

WHOX VPN is not offered and must not be used in the following jurisdictions:Russia, United Arab Emirates, Qatar, Iran, and China. You are responsible for ensuring that your use of the Services is lawful in your location. We may restrict access or features to comply with applicable laws and store policies.

18) Security & Incident Notices

We implement technical and organizational measures designed to protect information against unauthorized access, loss or misuse, including using PCI‑DSS compliant payment processing through Stripe and secure integrations with app stores and Cryptomus. However, no method of transmission or storage is 100% secure. Where legally required, we will notify supervisory authorities and affected users of a personal data breach within applicable statutory deadlines.

19) Children

The Services are intended for users aged 18 and over. We do not knowingly collect information from children.

20) Automated Decision‑Making

We do not use automated decision‑making that produces legal or similarly significant effects about you.

21) Changes

We may update this Policy from time to time. We actively monitor updates to the UAE PDPL, including forthcoming executive regulations expected to progress during 2025, and we will incorporate any new binding requirements. We also commit to re‑assess the need for a Data Protection Officer (DPO) and for Data Protection Impact Assessments (DPIAs) as our scale or processing activities change.

22) Contact

If you have questions about this Policy or your privacy rights, contact us at [email protected].